API Key Mismanagement in Claude Code Product
CVE-2026-103012

2LOW

Key Information:

Vendor

Anthropic

Vendor
CVE Published:
30 September 2026

What is CVE-2026-103012?

Claude Code has a vulnerability where an insecure API key may be utilized during a session for organizational settings, even if the user has authenticated correctly via their Enterprise or Team account. When the stored API key is rejected, the session can begin without the organization's policy restrictions, leading to potential security lapses. This issue arises when a device retains a stored API key from previous sessions. Organizations are advised to ensure manual updates to the latest version to mitigate the risks posed by this vulnerability.

Affected Version(s)

@anthropic-ai/claude-code 2.0.68 < 2.1.260

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.